Palo Alto Networks PAN-OS是美国Palo Alto Networks公司的一款下一代防火墙软件。 Palo Alto Networks PAN-OS 存在安全漏洞,该漏洞源于数据包处理机制存在漏洞。远程攻击者利用该漏洞可以重新启动基于硬件的防火墙。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Palo Alto Networks | Cloud NGFW | All |
unaffected |
| Palo Alto Networks | PAN-OS | 9.0.0< 9.0.17-h4 |
affected |
9.1.0< 9.1.17 |
affected | ||
10.1.0< 10.1.12 |
affected | ||
10.2.0< 10.2.8 |
affected | ||
11.0.0< 11.0.3 |
affected | ||
11.1.0 |
unaffected | ||
| Palo Alto Networks | Prisma Access | All |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | PAN-OS | 9.0.0 ~ 9.0.17-h4 | - |
|
| Palo Alto Networks | Cloud NGFW | - | - |
|
| Palo Alto Networks | Prisma Access | - | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-3382 | 7.5 HIGH | PAN-OS: Firewall Denial of Service (DoS) via a Burst of Crafted Packets |
| CVE-2024-3384 | 7.5 HIGH | PAN-OS: Firewall Denial of Service (DoS) via Malformed NTLM Packets |
| CVE-2024-3383 | 7.4 HIGH | PAN-OS: Improper Group Membership Change Vulnerability in Cloud Identity Engine (CIE) |
| CVE-2024-3386 | 5.3 MEDIUM | PAN-OS: Predefined Decryption Exclusions Does Not Work as Intended |
| CVE-2024-3387 | 5.3 MEDIUM | PAN-OS: Weak Certificate Strength in Panorama Software Leads to Sensitive Information Disc |
| CVE-2024-3388 | 4.1 MEDIUM | PAN-OS: User Impersonation in GlobalProtect SSL VPN |
No comments yet